Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 20, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
258391 9.3 危険 マイクロソフト - Microsoft Excel における任意のコードを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2010-3235 2010-10-27 15:17 2010-10-12 Show GitHub Exploit DB Packet Storm
258392 9.3 危険 マイクロソフト - Microsoft Excel における任意のコードを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2010-3234 2010-10-27 15:17 2010-10-12 Show GitHub Exploit DB Packet Storm
258393 9.3 危険 マイクロソフト - 複数の Microsoft 製品における任意のコードを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2010-3231 2010-10-27 15:16 2010-10-12 Show GitHub Exploit DB Packet Storm
258394 9.3 危険 マイクロソフト - Microsoft Excel における整数オーバーフローの脆弱性 CWE-189
数値処理の問題
CVE-2010-3230 2010-10-27 15:16 2010-10-12 Show GitHub Exploit DB Packet Storm
258395 9.3 危険 マイクロソフト - 複数の Microsoft 製品におけるスタックベースのバッファオーバーフローの脆弱性 CWE-94
コード・インジェクション
CVE-2010-3221 2010-10-27 15:16 2010-10-12 Show GitHub Exploit DB Packet Storm
258396 9.3 危険 マイクロソフト - 複数の Microsoft 製品におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2010-3214 2010-10-27 15:15 2010-10-12 Show GitHub Exploit DB Packet Storm
258397 9.3 危険 マイクロソフト - Microsoft Word および Microsoft Office における任意のコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2010-3220 2010-10-27 15:15 2010-10-12 Show GitHub Exploit DB Packet Storm
258398 9.3 危険 マイクロソフト - Microsoft Word における任意のコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2010-3219 2010-10-27 15:14 2010-10-12 Show GitHub Exploit DB Packet Storm
258399 9.3 危険 マイクロソフト - Microsoft Word におけるヒープベースのバッファオーバーフローの脆弱性 CWE-94
コード・インジェクション
CVE-2010-3218 2010-10-27 15:14 2010-10-12 Show GitHub Exploit DB Packet Storm
258400 9.3 危険 マイクロソフト - Microsoft Word における任意のコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2010-3217 2010-10-27 15:14 2010-10-12 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 21, 2026, 4:01 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
198321 5.4 MEDIUM
Network
bozdoz leaflet_map The Leaflet Map WordPress plugin before 3.0.0 does not escape some shortcode attributes before they are used in JavaScript code or HTML, which could allow users with a role as low as Contributors to … CWE-79
Cross-site Scripting
CVE-2021-24468 2024-11-21 14:53 2021-08-2 Show GitHub Exploit DB Packet Storm
198322 5.4 MEDIUM
Network
wpdevart youtube_embed\
_playlist_and_popup
The YouTube Embed, Playlist and Popup by WpDevArt WordPress plugin before 2.3.9 did not escape, validate or sanitise some of its shortcode options, available to users with a role as low as Contributo… - CVE-2021-24464 2024-11-21 14:53 2021-08-2 Show GitHub Exploit DB Packet Storm
198323 8.8 HIGH
Network
ays-pro image_slider The get_sliders() function in the Image Slider by Ays- Responsive Slider and Carousel WordPress plugin before 2.5.0 did not use whitelist or validate the orderby parameter before using it in SQL stat… - CVE-2021-24463 2024-11-21 14:53 2021-08-2 Show GitHub Exploit DB Packet Storm
198324 8.8 HIGH
Network
ays-pro photo_gallery The get_gallery_categories() and get_galleries() functions in the Photo Gallery by Ays – Responsive Image Gallery WordPress plugin before 4.4.4 did not use whitelist or validate the orderby parameter… - CVE-2021-24462 2024-11-21 14:53 2021-08-2 Show GitHub Exploit DB Packet Storm
198325 8.8 HIGH
Network
ays-pro faq_builder The get_faqs() function in the FAQ Builder AYS WordPress plugin before 1.3.6 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB c… - CVE-2021-24461 2024-11-21 14:53 2021-08-2 Show GitHub Exploit DB Packet Storm
198326 8.8 HIGH
Network
ays-pro popup_box The get_fb_likeboxes() function in the Popup Like box – Page Plugin WordPress plugin before 3.5.3 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to t… - CVE-2021-24460 2024-11-21 14:53 2021-08-2 Show GitHub Exploit DB Packet Storm
198327 8.8 HIGH
Network
ays-pro survey_maker The get_results() and get_items() functions in the Survey Maker WordPress plugin before 1.5.6 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the g… - CVE-2021-24459 2024-11-21 14:53 2021-08-2 Show GitHub Exploit DB Packet Storm
198328 8.8 HIGH
Network
ays-pro popup_box The get_ays_popupboxes() and get_popup_categories() functions of the Popup box WordPress plugin before 2.3.4 did not use whitelist or validate the orderby parameter before using it in SQL statements … - CVE-2021-24458 2024-11-21 14:53 2021-08-2 Show GitHub Exploit DB Packet Storm
198329 8.8 HIGH
Network
ays-pro portfolio_responsive_gallery The get_portfolios() and get_portfolio_attributes() functions in the class-portfolio-responsive-gallery-list-table.php and class-portfolio-responsive-gallery-attributes-list-table.php files of the Po… - CVE-2021-24457 2024-11-21 14:53 2021-08-2 Show GitHub Exploit DB Packet Storm
198330 7.2 HIGH
Network
ays-pro quiz_maker The Quiz Maker WordPress plugin before 6.2.0.9 did not properly sanitise and escape the order and orderby parameters before using them in SQL statements, leading to SQL injection issues in the admin … CWE-89
SQL Injection
CVE-2021-24456 2024-11-21 14:53 2021-08-2 Show GitHub Exploit DB Packet Storm